Skip to privacy policy
AuraBack to Aura

Privacy at Aura

Privacy Policy

Effective August 20, 2026

Aura is designed so your detailed migraine and health-context records remain in protected app storage on your device or in the private CloudKit database associated with your iCloud account. We do not use that sensitive health context for advertising or marketing.

State and European privacy notice. The sections on U.S. state privacy rights and European users explain additional rights that may apply based on where you live.
Information we collectTracking technologiesHow we share informationU.S. state privacy rightsNotice to European usersContact us

1. Scope and controller

Orion Designs LLC, 6513 Harold Ave, Cocoa, Florida 32927, USA (“Orion,” “we,” “us,” or “our”) operates Aura, a personal migraine-tracking and informational iPhone app. This Privacy Policy describes how we process personal information through the Aura app, Aura’s public website, our support activities, and our marketing measurement (collectively, the “Service”).

The website does not offer an account, health-data entry, or checkout. The app does not ask you to create a separate Aura account. When iCloud is available, app records are associated with your Apple Account through Apple’s private CloudKit service. Orion does not operate its own server database containing your detailed migraine and health-context records.

2. Personal information we collect

Information you provide or create

  • Health and app-content data. Information you enter about migraine episodes, symptoms, severity, aura, pain location, possible triggers, functional impact, notes, medications, supplements, schedules, doses, treatment outcomes, prescribing clinicians, treatment photos, cycle context, travel, and preferences.
  • Communications data. Information in messages you send to our support or privacy addresses, including your email address and the content of your request.

Optional Apple sources and device features

You control whether Aura can use optional Apple sources and features. Aura requests permission only when the related feature needs it.

  • Health. Aura reads selected Health data. Raw Health samples remain in Apple Health; Aura stores daily aggregates such as sleep, heart rate, heart-rate variability, daylight, state of mind, and optional cycle indicators.
  • Weather and location. Aura briefly processes your location, rounds it to roughly a neighborhood-sized area, and sends the rounded coordinate to Apple WeatherKit. Aura stores resulting context such as pressure and UV, not the coordinate itself.
  • Calendar. If you grant full Calendar access, Aura examines event titles and dates to identify likely travel and stores matched travel details such as title, dates, and time-zone context.
  • Photos and Camera. Aura processes only the treatment photo you select or take and saves a reduced copy with the treatment record. Apple’s photo picker does not give Aura broad access to your photo library.
  • Notifications and system surfaces. If you enable them, notifications, widgets, shortcuts, and Live Activities can display migraine or medication information outside the open app, including on the Lock Screen.

Information from third parties

  • Apple. Apple provides purchase status and transaction information needed to complete and restore App Store purchases. Apple also provides the iCloud, Health, WeatherKit, Calendar, photo-picker, Camera, notification, and system services you choose to use.
  • RevenueCat. RevenueCat provides subscription status, product identifier, purchase and renewal status, expiration, cancellation, billing-issue, and refund information associated with a pseudonymous app-user identifier.
  • AppsFlyer. When marketing measurement is enabled, AppsFlyer provides install, session, and campaign attribution information associated with a pseudonymous AppsFlyer identifier.

Information collected automatically

RevenueCat and AppsFlyer may process limited app and device technical data, identifiers, interaction events, network information, general location derived from an IP address, and subscription information as described below. Aura’s website host may process technical request data such as IP address, browser and device type, requested page, and timestamp to deliver, secure, and troubleshoot the website.

3. Cookies, tracking, and marketing measurement

Website

Aura’s public website does not add advertising cookies, analytics cookies, pixels, local-storage tracking, or a behavioral advertising service. Its hosting provider may use essential technologies or request logs to deliver and protect the website. Because Aura does not add website tracking, browser “Do Not Track” or Global Privacy Control signals do not change Aura’s website behavior.

App

Marketing measurement is enabled by default in the app and can be turned off at any time in Aura Settings. While enabled, AppsFlyer may process ordinary install, session, campaign, network, and app/device technical information together with a pseudonymous AppsFlyer identifier.

Aura sends only a limited allowlist of app-interaction events: onboarding started, paywall viewed, onboarding completed, trial started, and paid subscription started. Event properties are limited to product identifier, offer type, app version, and timestamp.

Aura asks for App Tracking Transparency permission before AppsFlyer’s first measurement session. If you grant permission, AppsFlyer may collect Apple’s advertising identifier (IDFA). AppsFlyer may also collect Apple’s identifier for vendors (IDFV). If permission is denied or restricted, IDFA is unavailable and attribution may continue through IDFV, Apple’s SKAdNetwork and AdAttributionKit, and aggregate or modeled reporting. While measurement is enabled, Aura may supply the AppsFlyer identifier to RevenueCat to connect subscription lifecycle events with campaign reporting.

Turning off Marketing measurement stops future AppsFlyer measurement from Aura and removes future AppsFlyer attribution sharing from RevenueCat. It does not erase information a provider processed before you turned it off. RevenueCat remains active for purchase processing, subscription access, and restores.

4. How we use personal information

We use personal information to:

  • provide, operate, secure, and troubleshoot the Service;
  • store and sync your records through the local and Apple services you select;
  • unlock Premium, process and restore purchases, and understand subscription performance;
  • run pattern analysis and a personalized risk model on your device using daily aggregates;
  • measure the effectiveness of app-install and subscription campaigns when Marketing measurement is enabled;
  • respond to support, privacy, and accessibility requests;
  • comply with law, legal process, and enforceable government requests; and
  • protect the rights, privacy, safety, and property of Orion, our users, service providers, and the public.

Aura’s pattern analysis and personalized model run on your device. Model inputs use daily aggregates rather than raw Health samples, exact location, or full Calendar contents. We do not use your personal information to train a generalized artificial intelligence model, and Aura does not make automated decisions that produce legal or similarly significant effects.

Aura does not include migraine symptoms, medications, treatment photos, Health data, cycle information, weather context, Calendar details, pain-map selections, notes, or location in AppsFlyer events, RevenueCat customer attributes, advertising audiences, or ad-network payloads.

5. How we share personal information

We may share personal information with:

  • Service providers. Apple, RevenueCat, AppsFlyer, and the website hosting provider process the limited data described in this Policy to provide their services.
  • Third parties you choose. If you export or share a report, CSV, backup, or other file, Aura hands the file to the destination you select through Apple’s share sheet. The recipient, app, or storage provider then controls its copy.
  • Professional advisers. Lawyers, auditors, insurers, and other advisers where reasonably necessary for their services.
  • Authorities and others. Government authorities or other parties when reasonably necessary to comply with law, protect rights or safety, investigate harmful activity, or establish and defend legal claims.
  • Business transferees. Parties to a proposed or completed financing, merger, acquisition, reorganization, insolvency, or sale of some or all of Orion’s business or assets, subject to appropriate confidentiality and legal protections.

We do not sell personal information for money. Our use of AppsFlyer for app-install and subscription attribution may be treated as “sharing,” targeted advertising, or a “sale” under some U.S. state privacy laws even though no money is exchanged. You can opt out by turning off Marketing measurement in Aura Settings or by contacting us.

6. Retention and deletion

Records in Aura remain until they are removed through controls Aura makes available, through Apple’s storage controls, or under Apple’s iCloud behavior. Aura does not currently offer one global delete control, and some derived values cannot be deleted individually in the app. Resetting Aura’s onboarding does not delete CloudKit records; deleting the app may not delete records already stored in iCloud.

Limited local preferences and event-deduplication markers remain only as needed to operate the app and honor your choices. We retain support and privacy communications as reasonably needed to respond, keep appropriate records, comply with law, and establish or defend claims.

Apple, RevenueCat, AppsFlyer, and the website host retain the data they process according to their own policies and legal obligations. We consider the amount, nature, and sensitivity of information, the purposes of processing, risk of harm, and legal requirements when determining an appropriate retention period. When information is no longer needed, we delete or anonymize it, or isolate it from further processing until deletion is possible.

7. Security

Aura uses iOS file protection, Apple’s private CloudKit database, access controls, and data minimization to protect your records. We also use reasonable technical and organizational safeguards for personal information we control. Security risk is inherent in all technology, so we cannot guarantee absolute security, uninterrupted synchronization, or error-free storage.

8. Your choices

  • Change Health, Location, Calendar, Camera, photo, notification, and other permissions in Aura or iOS Settings.
  • Turn Marketing measurement off in Aura Settings and manage App Tracking Transparency in iOS Settings.
  • Edit or delete individual Aura records where the app provides those controls and manage Aura’s iCloud storage through Apple.
  • Choose whether to export or share information and manage the Lock Screen visibility of notifications, widgets, and Live Activities.
  • Contact privacy@joinmetric.com to make a privacy request.

Turning off a permission stops future access but does not automatically remove information Aura already stored from that source. If you decline information needed for an optional feature, that feature may not work, but manual migraine tracking remains available.

9. U.S. state privacy rights notice

This section applies to residents of U.S. states whose privacy laws apply to Orion and grant the rights described below. These rights are not absolute, differ by state, and may be subject to exceptions.

Depending on your state, you may have the right to request information about our collection, use, disclosure, sale, or sharing of personal information; access a copy; correct inaccuracies; delete information; obtain a portable copy; opt out of sales, targeted advertising, or certain profiling; appeal a denied request; and exercise your rights without unlawful discrimination.

We do not use personal information for profiling that produces legal or similarly significant effects. We do not use sensitive health information to infer characteristics for advertising. We do not have actual knowledge that we sell or share the personal information of anyone under 16.

Information practices in the preceding 12 months

Personal informationPurposesDisclosed toSold or shared
App content and health context, including sensitive health information and selected photosApp features, storage, sync, and on-device analysisApple when you use its services; destinations you chooseNo
Device identifiers, app interaction, network, and related technical informationApp operation, security, website delivery, and marketing measurementApple, AppsFlyer, RevenueCat, and website hostAppsFlyer measurement may be considered a sale or sharing under some state laws
Purchase and subscription informationPurchases, Premium access, restores, and attributionApple, RevenueCat, and limited events to AppsFlyerLimited AppsFlyer attribution may be considered sharing
Support and privacy communicationsResponding to requests and legal complianceService providers and professional advisers as neededNo

How to exercise these rights

Email privacy@joinmetric.com with “Privacy Request” in the subject line and describe the right you wish to exercise. To opt out of AppsFlyer measurement immediately, turn off Marketing measurement in Aura Settings. We may ask for information reasonably necessary to verify your identity, residency, and request. Because Aura has no separate account and Orion generally cannot access detailed records in your private CloudKit database, we may direct you to applicable in-app or Apple controls when we cannot identify or access the requested record.

Where permitted, an authorized agent may submit a request for you. We may require proof of the agent’s authority and may ask you to verify your identity or confirm the request directly. If your state provides an appeal right, reply to our decision with “Privacy Appeal” in the subject line. California residents may also submit a “Shine the Light Request” at the same email address. Nevada residents may use the same address to request an opt-out of future covered sales.

10. Notice to European users

This section applies to individuals in the European Economic Area and United Kingdom (“Europe”). “Personal information” in this Policy includes “personal data” under the EU General Data Protection Regulation and UK GDPR. Orion Designs LLC is the controller for processing covered by this Policy. Contact details are provided below.

Legal bases

We rely on the following legal bases, as applicable:

PurposeInformationLegal basis
Service delivery and subscriptionsApp content, device, Apple-service, purchase, and subscription informationPerformance of a contract
Health-related app featuresHealth and other special-category informationYour explicit choices and consent, including permissions you grant for optional sources and features
Security, support, and service improvementDevice, technical, and communications informationOur legitimate interests in operating, protecting, supporting, and improving the Service
Marketing measurementDevice identifiers, app interaction, campaign, and limited subscription informationConsent where required, including for IDFA; otherwise our legitimate interest in measuring campaign performance
Legal compliance and protectionInformation relevant to the request or claimCompliance with law and our legitimate interests in protecting rights, safety, and the Service

Your European privacy rights

Subject to applicable conditions and exceptions, you may ask us to provide access to your personal information; correct it; delete it; provide a portable, machine-readable copy; restrict processing; or object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing. You also have an absolute right to object to direct marketing.

Submit a request to privacy@joinmetric.com. We may ask for information to confirm your identity and process the request. You may also complain to the data-protection authority where you live or work, or where you believe a violation occurred. UK users can contact the Information Commissioner’s Office. EEA users can find their authority through the European Data Protection Board.

International transfers

Orion is based in the United States, and service providers may process personal information in the United States and other countries outside Europe. Where European personal information is transferred to a country without an applicable adequacy decision, we rely on a legally recognized transfer mechanism as applicable, such as the EU Standard Contractual Clauses, the UK International Data Transfer Addendum, another approved safeguard, or a lawful derogation. Contact us for available information about the safeguard relevant to a transfer.

11. Other sites and services

The Service may link to websites, apps, and services operated by third parties. We do not control those services or their privacy practices, and a link does not mean that Orion endorses or is affiliated with the third party. Review the privacy policy of each service you use. Provider policies include Apple Privacy, RevenueCat Privacy, and AppsFlyer Services Privacy.

12. Children

The Service is not intended for anyone under 18. If you are a parent or guardian and believe a child provided personal information to Orion in a way prohibited by law, contact us. If we learn that we collected such information without legally required consent, we will take appropriate steps to delete it.

13. Changes to this Policy

We may update this Policy from time to time. We will update the effective date and post the revised version here. If required by law, we will provide additional notice or obtain consent before a material change takes effect.

14. How to contact us

For privacy questions or requests, email privacy@joinmetric.com. For product support, email aurasupport@joinmetric.com.

Legal Department
Orion Designs LLC
6513 Harold Ave
Cocoa, FL 32927 USA

Please also read Aura’s Terms of Use.

Aura homePrivacyTerms